What the vulnerability does
01Description
Missing Authorization vulnerability in heoLixfy Flexible Woocommerce Checkout Field Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flexible Woocommerce Checkout Field Editor: from n/a through 2.0.1.
Explanation of Vulnerability in Simple Terms
02Summary
The Flexible Woocommerce Checkout Field Editor plugin for WordPress lacks proper authorization checks, allowing unauthenticated attackers to modify checkout fields and potentially inject malicious content. An attacker can alter form data without logging in, affecting site integrity and customer trust. Update immediately to a patched version.
What an attacker can do
03Attacker Capabilities
Modify WooCommerce checkout fields and inject malicious content without authentication.
Potential impact on your site
04Site Impact
Attackers can alter checkout forms, inject phishing content, or disrupt customer transactions without your knowledge.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
December 9, 2024
CVE published
April 28, 2026
Record updated